So I went to update my apps and was greeted with these warnings in FDroid. A quick and basic search online and in various communities yielded no news regarding a major compromise in Fennec and Mull, does anyone know more about this or have you seen any news regarding a vulnerability? Curious if this is a false positive or if there is something going on with firefox forks.
It’s still waiting on a repackaging effort
https://gitlab.com/relan/fennecbuild/-/merge_requests/63
Looks like the latest hurdle is that Firefox is relying on some Google-specific variables being present, which fails on AOSP
Mull at least has been fixed in the divestOS repo. I can’t speak to fennec as I don’t use it.
The version in the f-droid main repo is behind because of Mozilla changing their repo system thus screwing with the build process and at least for now currently requiring a compiler that doesn’t meet F-Droid’s (IMO slightly ridiculous) standards for allowable software.
Mull was fixed in the DivestOS repository as early as October 17th, but to do this you need to add to F-Droid and reinstall Mull.
Or you can install directly from Divest via FFupdater, or from their github (I use Obtainium for that).
How do you use obtainium to download from their repo? I’m trying but can’t seem to make it work.
When you got add the repo in Obtainium in the overrides section choose Fdroid Third party repo. Then in the app name field type mull
I apologize. I didn’t see that my Obtainium was actually pulling from the fdroid repo. I was able to add it to Obtainium from the Divest repo: https://divestos.org/fdroid/official/us.spotco.fennec_dos_21320020.apk
But I really doubt that it will trigger updates, since it’s tied to the current version apk.
I update my browsers and K9 via FFupdater, that’s where my confusion came from. And I thank you for calling me our, I just removed Mull from my Obtainium.
Mull from divestos repo works fine! Use FFupdater to install it or link the fdroid repo to your fdroid
Mull is fine if you use the divestos repo directly, but the f-droid version is behind